Specifications
Firewall Protection
158
ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308
Unless your selection from the Action drop-down list is BLOCK always, you also need to
make selections from the following drop-down list:
• Select Schedule
4. Click Apply to save your changes. The new rule is now added to the Inbound Services
table.
Configure LAN DMZ Rules
• Create LAN DMZ Outbound Service Rules
• Create LAN DMZ Inbound Service Rules
The LAN DMZ Rules screen allows you to create rules that define the movement of traffic
between the LAN and the DMZ.
The default outbound and inbound policies are to block all
traf
fic between the local LAN and DMZ network. You can then apply firewall rules to allow
specific types of traffic either going out from the LAN to the DMZ (outbound) or coming in
from the DMZ to the LAN (inbound).
There is no drop-down list that lets you set the default outbound policy as there is on the LAN
W
AN Rules screen.
You can change the default outbound policy by allowing all outbound
traffic and then blocking specific services from passing through the VPN firewall. You do so
by adding outbound service rules (see Create LAN DMZ Outbound Service Rules on
page 160).
To access the LAN DMZ Rules screen for IPv4 or to change existing IPv4 rules:
Select Security > Firewall > LAN DMZ Rules. In the upper right of the screen, the IPv4 radio
button is selected by default. The LAN DMZ Rules screen displays the IPv4 settings. (The
following figure contains examples.)
Figure 87.